信息网络安全 ›› 2014, Vol. 14 ›› Issue (12): 12-15.doi: 10.3969/j.issn.1671-1122.2014.12.003

• 技术研究 • 上一篇    下一篇


李斌1, 白淑君1, 宋怀刚2   

  1. 1.海军计算技术研究所,北京100841;
    2.92493部队,辽宁葫芦岛 125000
  • 收稿日期:2014-11-04 出版日期:2014-12-15
  • 通讯作者: 李斌
  • 作者简介:李斌(1977-),男,安徽,高级工程师,硕士,主要研究方向:信息安全;白淑君(1976-), 女,河南,高级工程师,硕士,主要研究方向:信息安全;宋怀刚(1974-),男,四川,工程师,本科,主要研究方向:信息安全。

A Homomorphic Encryption Scheme on Online DBMS with Multilevel Secure Mechanism

LI Bin1, BAI Shu-jun1, SONG Huai-gang2   

  1. 1. Navy Institute of Computing Technology, Beijing 100841, China;
    2.Troop 92493,Huludao Liaoning 125000,China
  • Received:2014-11-04 Online:2014-12-15

摘要: 随着在线数据库管理系统的广泛应用,需要对数据库中存储的敏感信息进行加密。运用同态加密技术的数据库加密方案可以实现不用解密而直接操作密文数据,从而降低了加密对应用性能的影响。多级安全机制能够为数据库管理系统提供更高层级的信息安全保护。文章针对在线数据库管理系统的特点,提出了一种具备多级安全机制的同态加密方案。该方案数据库服务器端配置了所有安全等级的加解密密钥,客户端仅配置与自身安全等级相适应的加解密密钥;包含字段和记录两层加密机制,层次清晰,运算简单;具备多级安全机制,高安全等级用户所在的客户端能够解密数据库服务器中的低安全等级数据;支持所有数据库关系操作。实验结果表明,文章密钥配置方案合理可行,加密方案加解密原理正确,支持多级安全等级机制。

关键词: 在线数据库管理系统, 同态加密, 多级安全机制

Abstract: Owing to online DBMS is used widely, sensitive information stored in database should be encrypted. To acquire higher performance, a technology about privacy homomorphism can be used. By using this technology, it is possible to manipulate encrypted information without decrypting them. DBMS with multilevel secure mechanism would have higher information protection level. A new encryption scheme on online DBMS with multilevel secure mechanism is provided in this paper. The server has keys to handle data with all secure levels, and the client only has the key suiting for its own level. It includes two-layer encryption mechanism on fields and records. The process of encryption and decryption has clear layer and simple calculation. It has multilevel secure mechanism. High secure level users can decrypt low secure level data. It supports all relation operations on database. The example shows that the provided encryption scheme truly has feasible key configuration programme, right encryption and decryption process and perfectly supports multilevel secure mechanism.

Key words: online DBMS, homomorphic encryption, multilevel secure mechanism
